A ransomware attack on Indonesia’s National Data Centre in June 2024 disrupted 282 public services, leaving critical government systems offline for weeks. The incident exposed how heavily public services now depend on digital infrastructure. Over the past two decades, immigration records, tax filings, civil registration, and other essential services have increasingly moved online, making secure government systems more important than ever.
That convenience comes with a cost: the same systems that eliminate trips to government offices also store the sensitive data criminals seek. When those systems fail, the breach raises a critical question: who ultimately bears the consequences?
Indonesia spent the past two decades pulling public records out of filing cabinets and onto centralized servers. ID records, tax data, health records, land certificates, all funneled into the same government databases. The goal is to provide faster, more consistent service delivery across a country spread over 17,000 islands.
Centralizing that data within the Temporary National Data Center created a single point of failure. A successful breach could disrupt government services nationwide rather than affecting just one office or agency. Indonesia’s Personal Data Protection Law only came into effect in 2022, years after much of the country’s digital transformation was already underway.
By then, many agencies had been managing sensitive records without consistent requirements for encryption, access controls, or broader security safeguards. As a result, data breaches continued to expose gaps between the pace of digitization and the development of protections designed to secure it.
Lessons from the 2024 National Data Center Attack
On June 20, 2024, Indonesia’s Temporary National Data Centre in Surabaya was hit by a ransomware attack carried out by the Brain Cipher group. Using code derived from the leaked LockBit 3.0 builder, the attackers disrupted critical public services, including passport applications and immigration processing.
Despite demanding an $8 million ransom, the Indonesian government refused to pay, making the incident the largest ransomware attack in the country’s history
Indonesia’s National Cyber and Crypto Agency confirmed that the Brain Cipher group was behind the breach. On July 3, the attackers handed over the decryption key for free, no payment required. What came out of the investigation was less about the attackers and more about the target: outdated software nobody had fixed with no working backup to fall back on.
The real-world fallout of a data center ransomware attack is felt directly by citizens through severe disruptions to essential public services. For instance, airport immigration lines grew heavily as officers were forced to rely on manual passport verifications. Furthermore, online registration portals for national examinations remained unresponsive for days, causing students to miss critical deadlines that could not be rescheduled.
Ransomware groups do not just lock files; they often steal the data first. That is what happened in this case, with identity numbers and health records taken before systems were encrypted. Restoring a website does not undo that exposure. Once sensitive information leaves the system, citizens may face the risk of fraud and misuse for years, not just weeks.
The 2024 attack was caused by both technical and management failures, such as unclear security responsibilities, weak emergency planning, and a lack of official accountability.
This shows that data breaches in Indonesia are usually due to broad systemic issues, not just technical flaws.
The 2024 attack was not an isolated incident but part of a broader pattern of cybersecurity failures. Previous major breaches include the 2021 BPJS Health data leak affecting 279 million people, the 2022 exposure of 105 million voter records, and the leak of 1.3 billion SIM card records.
Despite repeated public concern over these incidents, many of the underlying security weaknesses that enabled them remain unresolved.
Researchers analyzing the 2024 breach highlighted four recurring priorities for strengthening cyber resilience:
None of these recommendations require cutting-edge technology. They are fundamental cybersecurity controls that have long been recognized as essential for protecting critical systems and sensitive data.
Cybersecurity budgets tend to get approved right after a breach makes the news, then forgotten. That reactive cycle is expensive and slow. Agencies that fund detection before an incident, not after, catch problems while they are still small enough to contain.
Ransomware groups often move faster than most government defenses can adapt. Private security firms often spot new attack techniques first, simply because they are watching more networks across more industries at once. Government agencies rarely have that reach on their own. Shared incident data, joint drills, and common reporting standards are what actually close the gap – not just policy statements.
The IndoSec summit, Indonesia’s largest and most prestigious cybersecurity summit, brings together government cybersecurity leaders, critical infrastructure operators, and private security practitioners to address the challenges shaping the nation’s cyber landscape. Scheduled for 15–16 September 2026 at The Ritz-Carlton Jakarta, Pacific Place, the summit serves as a platform for cross-sector dialogue and collaboration to strengthen national cyber preparedness, incident response capabilities, and protection of critical systems.
Beyond policy discussions, the summit focuses on the operational realities faced by security teams — from responding to ransomware attacks and managing third-party risks to securing increasingly connected infrastructure. It brings together those responsible for defending essential services, enabling direct exchanges on the decisions, technologies, and practices that influence how organizations detect, respond to, and recover from cyber threats.
Why do Indonesia’s digitized public services keep getting breached?
Rapid centralization of citizen data outpaced security investment, leaving critical systems still protected by weak backups, patching, and access controls.
What kinds of incidents have hit Indonesia’s public sector?
Incidents range from large-scale ransomware attacks on national data centers to repeated leaks of voter, health, and identity records.
How many citizens have been affected by these breaches?
Individual incidents have exposed data belonging to hundreds of millions of Indonesians, including national identity numbers, addresses, and medical history.
What is the citizen impact of service outages?
Outages cause travel delays, stalled registrations, and blocked permits as essential services rely on centralized digital systems.
What would meaningfully reduce Indonesia’s breach risk?
Consistent patching, tested offline backups, network segmentation, and enforced compliance with the Personal Data Protection Law would close most gaps.